While the FTC Safeguards Rule isn’t new (It was originally released in 2003.), it did receive substantial updates in 2021. These updates were designed to help covered organizations keep up with the rapid evolution of modern technology. The original deadline for FTC Safeguards Rule compliance was December 9, 2022. However, the final deadline was extended by six months in the latest FTC Safeguards Rule update, and as of now, the deadline for FTC Safeguards Rule compliance is June 9, 2023.
According to the FTC’s Safeguards Rule Information Page:
“The Safeguards Rule applies to financial institutions subject to the FTC’s jurisdiction and that aren’t subject to the enforcement authority of another regulator under section 505 of the Gramm-Leach-Bliley Act, 15 U.S.C. § 6805. According to Section 314.1(b), an entity is a “financial institution” if it’s engaged in an activity that is “financial in nature” or is “incidental to such financial activities as described in section 4(k) of the Bank Holding Company Act of 1956, 12 U.S.C § 1843(k).”
How do you know if your business is a financial institution subject to the Safeguards Rule? First, consider that the Rule defines “financial institution” in a way that’s broader than how people may use that phrase in conversation. Furthermore, what matters are the types of activities your business undertakes, not how you or others categorize your company.”
Simply put, if you are an organization that handles customer financial data, but aren’t a bank, you are probably covered by the FTC Safeguards Rule and must show compliance to avoid business disruption and fines.
Kroll delivers more than a typical incident response retainer—secure a true cyber risk retainer with elite digital forensics and incident response capabilities and maximum flexibility for proactive and notification services.
Kroll retainers not only include mandatory compliance services like risk assessments and penetration testing, but also meets practical security needs like cloud security, tabletop exercises, and in the event of an incident, prioritized support.
Kroll has built the foundation and experience needed to handle any size of engagement, including for the world’s top companies in industries from media and entertainment to critical infrastructure.
We’ve developed a seasoned in-house team dedicated to providing you with the structure and management background needed to scale and adapt your FTC Safeguards Rule compliance program based on your business drivers.
Kroll also boasts a unique advantage: the insights provided by our world-class incident response practice, which feed our certified cyber experts the information they need to test against the exploits attackers are executing today.
Kroll understands that every organization has its own unique needs. This is why Kroll offers three different FTC Safeguards bundles, achieving the “right sized” offering for every organization that needs to satisfy the requirements.
Kroll’s FTC Safeguards Rule bundles are built to take the pain and confusion out of this new set of requirements. By offering three different levels of engagement, Kroll enables covered organizations to achieve compliance with a package that fits their needs.
If your organization handles customer financial information, then you are likely to be covered under the FTC Safeguards Rule. Thanks to Kroll’s extensive background in compliance and financial engagements along with our deep expertise in cybersecurity and IT compliance frameworks, we have the scalable solution for your organization.
The Support Bundle |
The Guide Bundle |
The Manage Bundle |
For organizations that choose to achieve compliance with FTC Safeguards requirements in-house but require some support. Includes:
|
For organizations that require additional guidance and services to comply with FTC Safeguards requirements. Includes:
|
For organizations that require substantial guidance and managed services to comply with FTC Safeguards requirements. Includes Guide Bundle Services and:
|
Kroll has extensive experience with industry and compliance standards such as NIST, GDPR, CCPA, CMMC, and many others.
Our team brings the depth and breadth of expertise needed to tackle complex challenges across a variety of financial services' needs.
Kroll's DNA as incident response leader expands our assessments beyond compliance mandates but on actionable remediation based on frontline threat intelligence.
Incident response, digital forensics, breach notification, managed detection services, penetration testing, cyber assessments and advisory.
Proactively identify your highest-risk exposures and address key gaps in your security posture. As the No. 1 Incident Response provider, Kroll leverages frontline intelligence from 3000+ IR cases a year with adversary intel from deep and dark web sources to discover unknown exposures and validate defenses.
Validate your cyber defenses against real-world threats. Kroll’s world-class penetration testing services bring together front-line threat intelligence, thousands of hours of cyber security assessments completed each year and a team of certified cyber experts — the foundation for our sophisticated and scalable approach.
Kroll’s multi-layered approach to cloud security consulting services merges our industry-leading team of AWS and Azure-certified architects, cloud security experts and unrivalled incident expertise.
Kroll delivers more than a typical incident response retainer—secure a true cyber risk retainer with elite digital forensics and incident response capabilities and maximum flexibility for proactive and notification services.
Red team security services from Kroll go beyond traditional penetration testing, leveraging our frontline threat intelligence and the adversarial mindset used by threat actors to push the limits of your information security controls.
Kroll’s field-proven incident response tabletop exercise scenarios are customized to test all aspects of your response plan and mature your program.
Kroll's cyber risk assessments deliver actionable recommendations to improve security, using industry best practices & the best technology available.
Manage cyber risk and information security governance issues with Kroll’s defensible cyber security strategy framework.
by Andrew Rathbun, Eric Zimmerman
by David White
by George Glass
by Dave Truman